Junglewise Threat Intelligence

CVE-2024-46783: Linux Kernel Denial of Service in tcp_bpf_sendmsg

CVE-2024-46783 · Severity: medium · CVSS 5.5 · Published 2024-09-18

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability in the Linux kernel's networking component could allow a local user to crash the system. The issue occurs when the kernel handles specific types of network traffic processed by BPF (Berkeley Packet Filter) programs. An exploit results in a complete system denial of service (kernel panic), impacting availability and ongoing operations.

Technical details

A vulnerability exists in net/ipv4/tcp_bpf.c within the Linux kernel due to improper handling of the 'copied' return value in tcp_bpf_sendmsg(). When messages are corked in psock->cork, flushing the last message can result in a sk_msg larger than the current message size. In tcp_bpf_send_verdict(), the 'copied' variable can become negative during error handling (e.g., __SK_DROP). This negative value is subsequently returned to sock_sendmsg_nosec, triggering a BUG_ON in net/socket.c. A local attacker can exploit this to cause a kernel panic (Denial of Service). The fix ensures that the function returns an error code instead of a negative byte count.

Affected products

  • Linux Linux Kernel 4.17 to 5.4.284, 5.5 to 5.10.226, 5.11 to 5.15.167, 5.16 to 6.1.110, 6.2 to 6.6.51, 6.7 to 6.10.10, 6.11-rc1 to 6.11-rc6

Timeline

  • 2024-08-20: other: Patch authored
  • 2024-09-18: advisory: NVD publication date

References

Related threats